Written by: Haim Ravia, Dotan Hammer
On July 21, 2026, the Israeli Privacy Protection Authority (PPA) imposed an administrative fine of NIS 256,000 (approximately USD 83,000) on a health maintenance organization (a public body) for failing to report a data security incident in a timely manner as required by the Data Security Regulations, 2017. This is the first administrative fine the PPA has imposed specifically for a failure to comply with the data breach notification obligation—marking a significant enforcement milestone under the enhanced powers granted to the PPA by Amendment 13, which took effect on August 14, 2025.
Amendment 13 significantly expanded the PPA’s enforcement authority, transitioning the regulator from a registry-based supervisor to a full enforcement agency with the power to impose administrative fines for cybersecurity violations. The data breach notification obligation requires database owners to report serious security incidents to the PPA “promptly” upon becoming aware of them.
The PPA’s decision to impose a fine specifically for the failure to report — rather than for the underlying breach itself — signals that the authority views the notification obligation as a substantive compliance requirement in its own right, not merely a procedural formality. Organizations operating in Israel should ensure they have established and tested security incident response and breach notification plans, as the PPA has indicated it will continue to prioritize enforcement of these obligations.
Click here to read the PPA’s announcement (in Hebrew).