Guide
Amendment 13 to Israel's Privacy Protection Law: what a private clinic must know
On 14 August 2025, Amendment 13 to Israel's Privacy Protection Law came into force — the most sweeping reform of Israeli privacy law since 1981. Medical data is defined by the law as "data of special sensitivity", so every private clinic — from a solo practice to a multi-branch chain — sits at the center of the change, facing a regulator with real enforcement teeth. This page is practical guidance for clinic owners, not legal advice.
Last updated: 2026-08-11
What changed in Amendment 13?
The amendment passed the Knesset in 2024 and took effect on 14 August 2025 after a one-year preparation period. It moves Israeli law closer to the European standard (GDPR) and shifts the center of gravity: less registration bureaucracy — far more ongoing accountability and enforcement.
- New definitions: the "sensitive data" category was replaced by "data of special sensitivity" — explicitly including medical, genetic and biometric data, alongside intimate-life data, location, financial data and more. The law also adopted the terms "database controller" and "holder", mirroring the European controller/processor split.
- Mandatory Data Protection Officer (DPO): for the first time in Israel, certain organizations must appoint a privacy protection officer — details below.
- Database registration narrowed: registration is now required mainly for public bodies and data brokers. Instead, a notification duty to the regulator applies to controllers holding especially sensitive data on more than 100,000 people.
- New enforcement powers for the Privacy Protection Authority (PPA): administrative monetary sanctions, investigation and supervision powers, and the authority to order unlawful data processing stopped.
- Enforcement in practice: the PPA has already imposed sanctions under the amendment — including a fine of about NIS 256,000 on the Meuhedet health fund for failing to immediately report a serious security incident — and has reportedly been managing over 100 enforcement cases.
Why are clinics particularly exposed?
Every clinic's patient database — records, diagnoses, treatments, imaging — is by its very nature a database of especially sensitive data. That means higher security requirements, a stricter reporting bar, and monetary sanctions calculated more severely where medical data is involved.
And in the day-to-day reality of many Israeli clinics, the gap between the law and the floor is wide: an Excel file with the patient list on the reception computer, photos and results sent over WhatsApp from private phones, one password shared by the whole team, and deletions or edits nobody can trace. None of it was done in bad faith — that's simply how things worked for years. But under Amendment 13, with a regulator that now has real enforcement powers, these are exactly the points that become genuine business risk.
A private clinic's core obligations
Privacy protection officer (DPO)
The appointment duty applies, among others, to organizations whose core activity is processing especially sensitive data on a significant scale — the law names hospitals and health funds as examples. Per the PPA's guidance, "significant scale" has no single numeric threshold: it is assessed by the number of patients, the volume and variety of data, processing frequency and retention period. A private clinic should assess its own position — ideally with legal counsel.
Mandatory documents under the Data Security Regulations
The Privacy Protection (Data Security) Regulations, 2017 apply to every database, even the smallest: a database definitions document, a security procedure, a systems inventory — and for databases at medium security level or above, periodic audits. A database holding medical data is generally classified at least at the medium security level, unless it is a very small database managed by an individual.
Access control and permission management
The regulations require personal, role-based access permissions, identification and authentication of every user, and logging of database access. One password shared by the whole team — the common clinic habit — does not meet this requirement.
Reporting serious security incidents
A serious security incident must be reported to the PPA immediately — without waiting for an internal investigation to conclude. Failure to report has become a real sanction trigger: per PPA publications, up to NIS 80,000 for a medium-security database and up to NIS 320,000 for a high-security one — precisely the basis of the Meuhedet fine.
Patient rights: access and correction
Every patient has the right to review the data held about them and to demand correction of data that is inaccurate, incomplete or outdated. A clinic must be able to actually locate the data and answer such a request — not just on paper.
Informed consent, documented
Processing personal data rests by default on informed consent: the patient must know what data is collected, why, and to whom it may be transferred. Consent you cannot prove is as good as consent never given — documenting it matters as much as obtaining it.
Practical steps to prepare
Map your data
Write down where patient data actually lives: the management software, Excel files, email, WhatsApp, drawers full of paper forms. You cannot protect what you don't know exists.
Prepare the mandatory documents
A database definitions document and a security procedure tailored to the clinic — who is responsible, which systems, which risks, what to do in an incident. These are the baseline requirements of the Data Security Regulations.
Move to personal permissions
Retire shared passwords. Every staff member gets their own user, with permissions matching what they actually need — the receptionist has no reason to see full clinical records.
Assess the DPO duty
Check, ideally with a privacy lawyer, whether the clinic must appoint a privacy protection officer under the scale tests — and if not, consider designating an internal owner for the topic anyway.
Set a breach-reporting procedure
Define in advance what counts as an incident, who notifies the PPA and through which channel — because the duty is immediate reporting, and there is no time to improvise in real time.
Train the team and choose the right tools
Most leaks start with a daily habit, not a hack. Train the staff, and make sure the management system you work in supports the requirements — permissions, logging, and data isolation.
How the right management system helps
Let's be honest: no software makes a clinic "Amendment 13 compliant" — compliance belongs to the organization, not the tool. But a system built around the law's principles closes, by default, the technical gaps that are hardest to close manually. Here is what that looks like in Levion:
Data isolation at the database level
Separation between clinics is enforced with Postgres RLS inside the database itself, not in application code — one clinic's query physically cannot touch another clinic's data.
Role-based permissions
Every user has their own identity and role-scoped permissions — the foundation the Data Security Regulations' access-control and permission-management requirements call for.
An audit log that cannot be rewritten
Every action is recorded in an append-only audit log: entries are only added, never edited and never deleted — a record you can rely on when you need to reconstruct who did what, and when.
Consent records
Patient consents are recorded with version, source and timestamp — so the question "did the patient consent, and to what exactly" has a documented answer.
Archive instead of delete, no medical data in exposed places
Patient records are archived, never deleted, so clinical history doesn't vanish; identifying medical data never appears in URLs or logs; and Levion's own platform administrators are structurally blocked from patient data. A data processing agreement (DPA) is signed with the clinic at onboarding.
Levion was designed from day one around the principles of Amendment 13 and the Data Security Regulations — but it is a compliance-supporting tool, not a substitute for compliance: the procedures, the training and the legal responsibility remain with the clinic.
Amendment 13 FAQ for clinics
Must every private clinic appoint a privacy protection officer?
Not automatically. The duty applies to public bodies, to data brokers holding data on over 10,000 people, to organizations conducting systematic monitoring at significant scale — and to those whose core activity is processing especially sensitive data on a significant scale (the law names hospitals and health funds as examples). Per the PPA's guidance, "significant scale" is assessed on the full circumstances with no single numeric threshold — so a private clinic needs a case-by-case assessment, ideally with a lawyer.
How large are the fines under Amendment 13?
The PPA can impose significant administrative monetary sanctions, which in serious cases may reach millions of shekels; the amount depends on the type of violation, the database's security level and the volume of data. Published examples: up to NIS 80,000 for failing to immediately report a serious incident in a medium-security database and up to NIS 320,000 for a high-security one — and in practice a fine of about NIS 256,000 was imposed on the Meuhedet health fund.
Does a small clinic still have to register its database?
In most cases, no longer: Amendment 13 narrowed registration mainly to public bodies and data brokers, and set a notification duty to the PPA only for controllers holding especially sensitive data on more than 100,000 people. But be clear — exemption from registration is not exemption from the law: the Data Security Regulations and all substantive duties apply to every database, of any size.
What counts as a "serious security incident" and what do you do?
Broadly: unauthorized use of, or harm to, data from the database — with the exact definition depending on the database's security level. Once such an incident becomes known, it must be reported to the PPA immediately, without waiting for the internal investigation to finish. The first sanction imposed under the amendment was for exactly that — a late report.
Can software solve Amendment 13 compliance by itself?
No. Good software closes the technical gaps — permissions, logging, data isolation, archiving — but compliance also includes written procedures, staff training, assessing the DPO duty and answering patient requests. The right system dramatically reduces the effort; it does not eliminate it.
Disclaimer: the information on this page is general information only, current as of the update date, and does not constitute legal advice or a substitute for it. How the duties apply depends on each clinic's specific circumstances — consult a lawyer specializing in privacy law.
Want to see it up close?
Book a personal demo — we'll walk through your own clinic's scenarios together.