Digital Health Companies and the Most Sensitive Category of Data
A startup building a health-metrics tracking app, a software vendor managing digital medical records for clinics, and a telemedicine platform connecting patients to physicians all handle information that Israeli law defines as especially sensitive. Medical data is not ordinary personal information. It reveals details about a person's physical and mental condition, treatments, diagnoses, and medications — information whose exposure can cause serious and irreversible harm to a person's privacy.
As more healthcare services move online, technology companies increasingly find themselves handling medical data even when they are not health organizations in the traditional sense. A cloud provider hosting medical records, an analytics company processing supposedly anonymized health data, and even a wearable device manufacturer may all be treated as processors of medical data for legal purposes.
This article reviews the key legal obligations applicable to medical technology providers and health companies in Israel, as of the date of this article.
The Legal Framework Protecting Medical Data in Israel
Protection of medical data in Israel rests on several complementary legal sources. The Privacy Protection Law, 5741-1981, as amended by Amendment 13 (in force since 14.8.2025), classifies medical data as "sensitive information" and imposes heightened obligations on those who process it, including with respect to the required security level and the rights of data subjects.
The Patient Rights Law, 5756-1996, establishes an explicit duty of medical confidentiality applicable to caregivers and medical institutions, and restricts the use of medical data to treatment purposes or purposes to which the patient has expressly consented. A technology company providing services to, or acting on behalf of, a medical institution is largely bound by the same restrictions through its service agreement with that institution.
In addition, the Ministry of Health periodically publishes circulars and guidance concerning the retention of digital medical records, including requirements relating to cloud storage, backup, and access control. Companies providing technology infrastructure to healthcare entities should examine whether ministry-specific guidance applies to them, in addition to the general obligations under the Privacy Protection Law.
It is important to emphasize: Amendment 13 narrowed the general database registration requirement so that it now applies mainly to public bodies and to "data brokers" — entities whose core business is collecting personal information for transfer to others, above a threshold set by law. That said, exceptionally large databases containing highly sensitive information, including medical data, may still trigger a notification duty to the Privacy Protection Authority even where no registration requirement applies. Each case should be assessed against the current statutory language.
Heightened Security Requirements for Medical Data Databases
The Privacy Protection Regulations (Data Security), 5777-2017, classify databases into different security tiers based on the sensitivity and scope of the data involved. A database containing medical data is generally classified at the high security tier, which imposes an extensive set of obligations on the database owner and holder: appointing a data security officer, conducting periodic risk assessments and penetration testing, encrypting data at rest and in transit, implementing permission-based access controls, logging security events, and maintaining organized procedures for managing subcontractors.
What This Means in Practice
- Establishing a formal data security policy that is updated on an ongoing basis
- Restricting access to medical data to employees who require it for their role
- Encrypting medical data both in storage and in transit between systems
- Maintaining access logs that allow tracking of every action performed on the data
- Conducting periodic security testing and incident response exercises
Many medical technology companies choose to adopt recognized international standards (such as ISO 27001 or health-specific frameworks) as the basis for their security policies, alongside compliance with Israel's specific statutory requirements.
Contractual Obligations Between MedTech Providers and Healthcare Entities
When a technology company provides services to a clinic, hospital, health fund, or health insurer, it typically acts as a "holder" of data on behalf of the database owner. The allocation of responsibility between the parties must be anchored in a detailed agreement clarifying which party is responsible for which aspects of data protection.
A well-drafted medical data processing agreement should address, among other things, the permitted purposes for using the data, restrictions on transferring data to third parties or abroad, the medical institution's right to conduct security audits of the provider, the provider's duty to promptly report any suspected security incident, and procedures for deleting the data upon termination of the engagement.
Companies processing medical data for international clients should also examine GDPR restrictions and the status of Israel's partial adequacy recognition from the European Union, since this status is subject to periodic review and may affect how data transfers should be structured.
The Duty to Report Security Incidents Involving Medical Data
Amendment 13 to the Privacy Protection Law introduced, for the first time, an explicit duty to report serious security incidents to the Privacy Protection Authority. Where medical data is involved — treated as especially sensitive information — the threshold for classifying an incident as "serious" tends to be lower, and the consequences of a leak can be particularly significant for the affected data subjects.
A medical technology company should establish, in advance, a security incident response procedure that includes rapid identification of the incident, assessment of the scope of exposure, notification of the database owner (where the company acts as a holder on its behalf), and evaluation of whether reporting to the Privacy Protection Authority and to affected data subjects is required under law.
A separate article on this site addresses in detail the specific obligations following a data breach incident, and is worth reviewing alongside the medical-data-specific aspects discussed here.
What Medical Technology Companies Should Actually Do
Legal compliance is not a one-time task but an ongoing process. The following are key steps recommended for every medical technology company and digital health company:
- Fully map every type of medical data collected, its sources, and the purposes of processing
- Assess the required security level under the Data Security Regulations and update security policy accordingly
- Evaluate whether appointment of a privacy officer is required under the applicable statutory conditions
- Update privacy policies and service agreements to reflect the nature of the medical data being processed
- Enter into detailed data processing agreements with every vendor and healthcare entity the company works with
- Establish a security incident response procedure with clear reporting stages
- Examine restrictions on transferring medical data abroad, including to international cloud providers
Companies beginning to develop a digital health product benefit significantly from incorporating privacy and data security considerations at the design stage (Privacy by Design), rather than adding them later once the product is already on the market.
Medical Privacy as a Foundation of Trust
Medical data enjoys heightened protection under Israeli law, and the consequences of mishandling it — both legal and business consequences — can be significant. Medical technology companies and health organizations need to combine a thorough understanding of the Privacy Protection Law, the Patient Rights Law, and the Data Security Regulations with appropriate contractual and operational mechanisms.
Patients' and customers' trust in a health technology product depends heavily on the company's ability to demonstrate that it protects the most sensitive information they share with it. Early investment in building an appropriate compliance infrastructure pays off both legally and commercially.
Companies are advised to periodically review their existing privacy policies, agreements, and security procedures in light of the ongoing regulatory developments in this area.
The information contained in this article is general in nature and does not constitute legal advice. For advice tailored to the specific circumstances of your company, we invite you to contact our firm.