Cybersecurity Policy Report, Israeli DPA Publishes Report on Data Security Incidents in Hospitals, (Sep 16, 2024)
By Tony Foley
Israel’s Privacy Protection Authority (PPA) published a report yesterday outlining findings from an investigation revealing “significant deficiencies” in the data security practices of the hospital sector in the country.
In news release, PPA noted that hospitals processed a high volume of sensitive personal information, including comprehensive medical records, demographic details, financial information, and family relationships. The report, which may be accessed from the news release but is available only in Hebrew, finds that a main concern regarding hospital data security is the extensive access to the information afforded to various parties within a hospital, as well as the transfer of such information between the various medical bodies, including other hospitals, health insurance funds, and the Ministry of Health. Specifically, PPA made the following findings:
About 71% of the 28 hospitals studied were at a high level of compliance, with 20% at a medium level, regarding Israeli information security requirements;
With respect to database management, one-third of hospitals were at a low level of compliance, with another one-third at the mid-level; and
Half of the hospitals were at a low or medium level of compliance regarding organizational control and corporate governance.
Regarding transfers of information between public bodies, the report found significant noncompliance with Israeli law and regulatory provisions. Only 7% of hospitals had a high level of compliance, with 30% complying only at a low level. Finally, the vast majority (78%) of hospitals were found to hand over information to other entities without performing registration, or while performing only partial registration, as required by law.
PPA said all of the hospitals subject to its investigation received specific instructions to correct the identifies deficiencies and that a follow-up audit revealed that 57% of such deficiencies were fully addressed.
News: InternationalLegislation DataSecurity DataPrivacy