Back to Browse

Maccabi Health MCP Server

Developer ToolsModerate6.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Read your own Maccabi Healthcare records: labs, prescriptions, visits, referrals, PDFs.

About

Read your own Maccabi Healthcare records: labs, prescriptions, visits, referrals, PDFs.

Security Report

6.2
Moderate6.2Moderate Risk

This MCP server provides access to sensitive Israeli healthcare records through the Maccabi portal. While authentication is properly required and the code demonstrates reasonable defensive practices (input validation, error handling), there are moderate security concerns: (1) session management relies on background keep-alive processes that could be exploited, (2) sensitive medical data is logged in error messages and stored in memory with limited lifecycle controls, (3) the server exposes broad healthcare data access without field-level permission controls, and (4) PDF processing lacks size enforcement consistency. The code quality is generally good but the sensitive nature of the data and permission scope warrant caution. Package verification found 1 issue.

4 files analyzed · 9 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

process_spawn

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-orenyomtov-maccabi-health": {
      "args": [
        "-y",
        "maccabi-health"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Maccabi Health

Ask an AI assistant for a second look at your lab results, scans, doctor visits, messages, referrals, and prescriptions.

npm license

Read your records from Maccabi Healthcare Services, the Israeli health fund, through a CLI or an AI assistant: laboratory history, doctor correspondence, visits, prescriptions, referrals, and supported original PDFs.

Unofficial and unaffiliated with Maccabi. You need your ID number (תעודת זהות) and access to the phone that receives the login code via SMS.

Getting started

Copy and paste this to your agent:

Analyze my blood test results, and tell me if my cholesterol is a problem

https://raw.githubusercontent.com/orenyomtov/maccabi-health/main/skills/maccabi-health/SKILL.md

Agents like Claude Code, Cowork, Codex, Cursor, Instinct, Muse, and ChatGPT Work can follow that.

Another option to get started is to run npx skills add orenyomtov/maccabi-health which installs that skill into Cursor, Claude Code, Codex and other local agents.

Install and sign in

npm install -g maccabi-health
maccabi-health login
maccabi-health labs --limit 10

Or, without a global install:

npx -y maccabi-health login
npx -y maccabi-health labs --limit 10

maccabi-health login asks for your ID and the SMS code in the terminal. If an agent prefers the user to sign in directly in the browser, maccabi-health login --http prints a URL that the user can be redirected to to login instead, and it writes to the same session file that the CLI uses.

If maccabi-health is not on your PATH after a global install, use the absolute path to the bin or stick with npx.

Sessions expire

Maccabi ends every session an hour after login, activity or not. A finished maccabi-health login starts a background keep-alive for that hour (a renewal every 240 seconds) and then returns, so later commands keep working until the hour is up. maccabi-health login --no-keep-alive skips it. maccabi-health logout stops it. The background process cannot extend the hour. Measurements are in SESSION-LIFETIME.md.

Privacy

Every record you read here is real medical data. Anything you hand to an assistant becomes part of that model's context and goes wherever that model runs.

Agent with a shell

Use the `maccabi-health` CLI to read my Maccabi records. 
Install with `npm install -g maccabi-health`. 
Run `maccabi-health` for the command index, `maccabi-health help` for the full reference, and `maccabi-health help COMMAND --json` for one command's exact arguments.

The CLI is usually the better surface there: no tool-cap fights, and JSON out of a pipe is something an agent can already filter and loop over.

MCP

claude mcp add maccabi-health -- npx -y maccabi-health mcp
codex mcp add maccabi-health -- npx -y maccabi-health mcp
gemini mcp add maccabi-health npx -y maccabi-health mcp

Cursor, in ~/.cursor/mcp.json:

{
  "mcpServers": {
    "maccabi-health": {
      "command": "npx",
      "args": ["-y", "maccabi-health", "mcp"]
    }
  }
}

maccabi-health mcp --http serves loopback Streamable HTTP with OAuth; see MCP.md.

Library

Install with:

npm install maccabi-health

Example usage:

import { connect, login } from "maccabi-health";

const pending = await login(idNumber);
await pending.sms();
const client = await pending.verify(smsCode);

const tests = await client.listTests({ year: 2025 });

pending.phones lists the SMS numbers; pass an index to sms() when there is more than one. A wrong code ends the attempt.

You can save await client.exportSession() and open it later with connect(session).

The methods are the same reads as the CLI.

Capabilities

ReadExamples
Test resultsValues, dates, units, ranges, historical comparisons and PDFs
MedicationPrescriptions, dispensing records and eligible PDFs
Medical recordsVisit notes, vaccinations, referrals and summaries
CorrespondenceSupported doctor inquiries, replies and documents
BillingQuarterly reports and report PDFs
ImagingStudy list, series, and per-image metadata. Preview JPEGs and raw pixel files are CLI-only; only 8-bit ultrasound has been checked live
Other readsCertificates, notifications, settings, and public provider search (often blocked by a bot challenge)

See the full capability reference.

Something not working?

Fix the bug and send a pull request. That is better than only opening an issue: each account has different records, so the maintainer often cannot reproduce what you saw. See Contributing.

Open an issue if you cannot fix it. Never paste medical records, ID numbers, cookies or session files. Security problems go through SECURITY.md.

All docs · Authentication · CLI guide · MCP transports · Changelog · API sources · Contributing · MIT license

Reviews

No reviews yet

Be the first to review this server!