NHS England has acknowledged that it concealed Palantir’s access to patient information.
NHS England has acknowledged that a crucial data protection document inaccurately represented who could access patients' medical records, failing to reveal the entire arrangement. Employees of Palantir, a US-based data analytics company, are able to view identifiable patient information within a portion of the new Federated Data Platform.
This admission came after a request from the National Data Guardian, the official body that advises the NHS on confidentiality matters. NHS England accepted the mistake and issued an apology, according to The Register.
“We acknowledge that the DPIA contained an error in its description of supplier access to data, and we are rectifying that mistake while apologizing for any confusion it has caused,” NHS England stated in its response. DPIA refers to the Data Protection Impact Assessment, a document intended to clarify this very matter.
Details on Palantir's Access
The access is located within the platform's National Data Integration Tenant. NHS England confirmed in May that certain supplier personnel can access identifiable patient data there for specific technical purposes, under NHS oversight.
The system is designed to assist the NHS in sharing data throughout the health service and to help address the care backlog. Palantir secured a £330 million contract to construct it in 2023, following £60 million in COVID-related contracts awarded without competition.
NHS England asserts that the supplier access is technically necessary. However, the National Data Guardian, Nicola Byrne, expresses uncertainty about being able to take that assertion at face value. “As an independent body not part of the platform’s operation, we are not in a position to independently verify that assessment,” she stated in an updated statement.
The Issue of ‘No Surprises’
Byrne is responsible for upholding the Caldicott Principles, which have governed patient confidentiality in the NHS since the 1990s. One of these principles is the “no surprises” guideline, which holds that individuals should not be taken by surprise regarding who can access their data.
This breach directly contradicts that principle. Byrne noted that the incident “has demonstrated how rapidly trust can erode if the ‘no surprises’ principle is not honored regarding who can access personal data and the reasons for it.”
She further emphasized that the strong public reaction reflects two concerns: people have a deep commitment to the confidentiality of their records, and many continue to feel uneasy about Palantir’s involvement in the NHS, a topic she highlighted as always being politically charged.
Criticism Beyond a Simple Error
Some critics argue that there is more at play than merely a typographical error. Sam Smith, coordinator at the campaign group medConfidential, believes that this framing allows NHS England to evade accountability.
“NHS England claims it was little more than a typo, but this stems from discouraging their expert staff from being truthful with leadership,” Smith told The Register. He described it as “another instance of the culture of fear that NHS England has fostered surrounding the platform.”
This controversy arises as scrutiny of Palantir’s work in the public sector is intensifying across Europe. France is moving away from Palantir in favor of a domestic competitor, while both France and Germany are supporting a European alternative for reasons related to sovereignty. In contrast, Britain currently maintains a different approach.
NHS England has stated it will fully implement the recommendations made by the National Data Guardian. However, whether this will restore public trust remains uncertain. As with other disputes regarding health data, while the numbers involved may be small and the solutions technical, the issue of transparency continues to persist.
Other articles
NHS England has acknowledged that it concealed Palantir’s access to patient information.
NHS England has acknowledged that its documentation did not reveal that Palantir personnel can access identifiable patient information within the Federated Data Platform.
