Check Point's Healthcare AI Deal Landed Six Days After a Federal Deadline to Patch Its Own Firewalls
Clalit, the health system covering more than 5 million Israelis, is getting a jointly built AI Gateway from Check Point. The release names no price, and it landed six days after US federal agencies were ordered to patch two exploited flaws in Check Point's own gear.
Vincent Jiang · 3 min read
A four-product deal with no price on it
On 1 October 2026, Check Point Software and Clalit Health Services announced a strategic partnership: a jointly developed AI Gateway for Clalit, plus Check Point's AI security, exposure management and workspace tools across its headquarters, 14 hospitals and more than 1,600 clinics, run by some 60,000 staff serving more than 5 million members 1. The release carries quotes from two chief executives, four product lines, and no money: no contract value, no term, no delivery dates 1. Israeli coverage calls it a "multi-million-dollar partnership," a figure that appears nowhere in the announcement itself 2.
Hospital attacks are the demand curve
Check Point's research arm counts cyberattacks on healthcare up more than 30% in two years, an average 2,268 per organization per week, the third most attacked sector 1. Clalit's security chief Avi Attia framed the buy as a move "from dealing with threats in wartime to building long-term defense infrastructure" after three years of war 1. That budget is contested: on 29 September, CrowdStrike listed its Falcon platform in the OpenAI Marketplace so enterprise customers can fund security out of existing OpenAI commitments 6.
The gatekeeper's own gateways were the exposure
The complication: while pitching hospitals an AI gatekeeper, Check Point spent late September under federal orders to fix its own gear. Two flaws rated 9.8 out of 10 are being exploited in the wild: CVE-2026-85102, pre-authentication remote code execution in Quantum and Spark VPN gateways, patched 9 September and attacked from 12 September; and CVE-2026-93616, a path-traversal zero-day in the management, logging and SmartEvent stack, exploited since 23 July 345. CISA listed both on 22 September and gave US federal agencies until 25 September to remediate 34. The vendor of the hospital gatekeeper was, that same week, under a deadline to patch the gateways it had already sold. Check Point says a handful of customers were attacked 5, and it is not a lone slip: ransomware crews have exploited other Check Point zero-days since June 5.
Clalit's answer, and the gap that remains
Clalit's case is in its own framing: "information security is not a limitation on innovation. It is the condition that allows us to move forward faster," chief executive Eytan Wirtheim said 1. A vendor that patches in public and names its own incidents is arguably the honest one. Unresolved: with no disclosed price, nobody outside the deal can weigh what the trust costs.
2 November is the next number
Check Point reports third-quarter results on 2 November 2026 7, arriving as revenue growth slows for a fourth straight quarter, from 6.7% year over year in Q3 2025 to 1.3% in Q2 2026 8. The AI-security pillar needs named logos like Clalit to be more than slide material.
Four straight quarters of slower revenue growth as Check Point pitches AI security
Data
| Revenue growth, % y/y | |
|---|---|
| Q3 2025 | 6.7% |
| Q4 2025 | 5.9% |
| Q1 2026 | 4.8% |
| Q2 2026 | 1.3% |
The gateway is sold; the invoice is not shown.
Deepdive
AI-generated from this story and its cited sources. Not investment advice.


