1. Home
  2. Guides
  3. Amendment 13 to Israel's Privacy Protection Law: what a private clinic must know

Guide

Amendment 13 to Israel's Privacy Protection Law: what a private clinic must know

On 14 August 2025, Amendment 13 to Israel's Privacy Protection Law came into force — the most sweeping reform of Israeli privacy law since 1981. Medical data is defined by the law as "data of special sensitivity", so every private clinic — from a solo practice to a multi-branch chain — sits at the center of the change, facing a regulator with real enforcement teeth. This page is practical guidance for clinic owners, not legal advice.

Last updated: 2026-08-11

What changed in Amendment 13?

The amendment passed the Knesset in 2024 and took effect on 14 August 2025 after a one-year preparation period. It moves Israeli law closer to the European standard (GDPR) and shifts the center of gravity: less registration bureaucracy — far more ongoing accountability and enforcement.

Why are clinics particularly exposed?

Every clinic's patient database — records, diagnoses, treatments, imaging — is by its very nature a database of especially sensitive data. That means higher security requirements, a stricter reporting bar, and monetary sanctions calculated more severely where medical data is involved.

And in the day-to-day reality of many Israeli clinics, the gap between the law and the floor is wide: an Excel file with the patient list on the reception computer, photos and results sent over WhatsApp from private phones, one password shared by the whole team, and deletions or edits nobody can trace. None of it was done in bad faith — that's simply how things worked for years. But under Amendment 13, with a regulator that now has real enforcement powers, these are exactly the points that become genuine business risk.

A private clinic's core obligations

Practical steps to prepare

  1. Map your data

    Write down where patient data actually lives: the management software, Excel files, email, WhatsApp, drawers full of paper forms. You cannot protect what you don't know exists.

  2. Prepare the mandatory documents

    A database definitions document and a security procedure tailored to the clinic — who is responsible, which systems, which risks, what to do in an incident. These are the baseline requirements of the Data Security Regulations.

  3. Move to personal permissions

    Retire shared passwords. Every staff member gets their own user, with permissions matching what they actually need — the receptionist has no reason to see full clinical records.

  4. Assess the DPO duty

    Check, ideally with a privacy lawyer, whether the clinic must appoint a privacy protection officer under the scale tests — and if not, consider designating an internal owner for the topic anyway.

  5. Set a breach-reporting procedure

    Define in advance what counts as an incident, who notifies the PPA and through which channel — because the duty is immediate reporting, and there is no time to improvise in real time.

  6. Train the team and choose the right tools

    Most leaks start with a daily habit, not a hack. Train the staff, and make sure the management system you work in supports the requirements — permissions, logging, and data isolation.

How the right management system helps

Let's be honest: no software makes a clinic "Amendment 13 compliant" — compliance belongs to the organization, not the tool. But a system built around the law's principles closes, by default, the technical gaps that are hardest to close manually. Here is what that looks like in Levion:

Levion was designed from day one around the principles of Amendment 13 and the Data Security Regulations — but it is a compliance-supporting tool, not a substitute for compliance: the procedures, the training and the legal responsibility remain with the clinic.

Amendment 13 FAQ for clinics

Must every private clinic appoint a privacy protection officer?

Not automatically. The duty applies to public bodies, to data brokers holding data on over 10,000 people, to organizations conducting systematic monitoring at significant scale — and to those whose core activity is processing especially sensitive data on a significant scale (the law names hospitals and health funds as examples). Per the PPA's guidance, "significant scale" is assessed on the full circumstances with no single numeric threshold — so a private clinic needs a case-by-case assessment, ideally with a lawyer.

How large are the fines under Amendment 13?

The PPA can impose significant administrative monetary sanctions, which in serious cases may reach millions of shekels; the amount depends on the type of violation, the database's security level and the volume of data. Published examples: up to NIS 80,000 for failing to immediately report a serious incident in a medium-security database and up to NIS 320,000 for a high-security one — and in practice a fine of about NIS 256,000 was imposed on the Meuhedet health fund.

Does a small clinic still have to register its database?

In most cases, no longer: Amendment 13 narrowed registration mainly to public bodies and data brokers, and set a notification duty to the PPA only for controllers holding especially sensitive data on more than 100,000 people. But be clear — exemption from registration is not exemption from the law: the Data Security Regulations and all substantive duties apply to every database, of any size.

What counts as a "serious security incident" and what do you do?

Broadly: unauthorized use of, or harm to, data from the database — with the exact definition depending on the database's security level. Once such an incident becomes known, it must be reported to the PPA immediately, without waiting for the internal investigation to finish. The first sanction imposed under the amendment was for exactly that — a late report.

Can software solve Amendment 13 compliance by itself?

No. Good software closes the technical gaps — permissions, logging, data isolation, archiving — but compliance also includes written procedures, staff training, assessing the DPO duty and answering patient requests. The right system dramatically reduces the effort; it does not eliminate it.

Disclaimer: the information on this page is general information only, current as of the update date, and does not constitute legal advice or a substitute for it. How the duties apply depends on each clinic's specific circumstances — consult a lawyer specializing in privacy law.

Want to see it up close?

Book a personal demo — we'll walk through your own clinic's scenarios together.

WhatsApp