How can a doctor be prevented from inadvertently entering a patient’s treatment summary into a public platform such as ChatGPT? And how can attackers be stopped from exploiting artificial intelligence to extract sensitive data from a hospital?
To address these risks, Clalit and Check Point have signed a multimillion-shekel strategic partnership to develop a security framework that will enable the health fund to expand its use of AI while protecting sensitive information.
The initiative comes against a backdrop of conflicting realities in healthcare. On the one hand, employees and medical staff are increasingly turning to tools such as ChatGPT and Gemini to streamline their work. On the other, the rapid digitization of healthcare systems has created new vulnerabilities.
Adv. Avivit Kotler, Clalit’s CISO, said the organization has faced a dramatic increase in cyber threats. “In recent years, and particularly since the outbreak of the war, we have been experiencing attack attempts from Iran and its proxies at rates hundreds of times higher than usual.”
“We are talking about tens of thousands of attacks per year,” she said.
According to Kotler, a turning point came with the ransomware attack that crippled Hillel Yaffe Medical Center, prompting the Ministry of Health to tighten its cybersecurity regulations.
Clalit already uses AI, but it has traditionally operated these systems within closed and isolated environments. A World Health Organization report says Clalit currently uses a platform from Aidoc, which is integrated directly into its internal imaging systems to manage medical algorithms, as well as local models that scan historical data to identify previously undiagnosed diseases.
These internal systems operate under the health fund’s organizational regulations. But the introduction of free, publicly available GenAI applications into clinics has created what Kotler describes as “an additional layer of risk.”
The concern is uncontrolled use. If a physician copies a medical summary containing personally identifiable information into an external AI-powered search engine, for example, sensitive information could potentially be exposed outside the organization.
The security gateway being developed by Clalit and Check Point is intended to prevent such incidents, enforce privacy rules and establish clear “guardrails” that allow staff to use AI tools and derive insights without compromising patient privacy.
The system will also have to address more complex and increasingly autonomous threats, including AI agents and third-party applications that connect to hospital systems. An AI agent responsible for automatically scheduling appointments, for example, could potentially gain access to sensitive information that is irrelevant to its task or attempt to transfer that data to an external server.
The security gateway is designed to monitor such agents in real time and block anomalous actions by external applications.
For Check Point, the partnership provides a large-scale environment for developing and deploying the technology across a healthcare system serving five million people in Israel. In return, Check Point will retain the intellectual property rights, with the goal of eventually commercializing and selling the platform.
Despite the close collaboration, Clalit says patient data will remain within the health fund. “The only information Check Point sees is metadata; they have absolutely no access to our patients’ data,” Kotler said.
Kotler estimates that the system will be widely deployed and fully meet the organization’s needs by the first quarter of 2027.










Leave a Reply