NHS England has admitted that a key data-protection document misstated who could see patients’ medical records. It did not disclose the whole arrangement. Staff at Palantir, the US data-analytics firm, can view identifiable patient data inside part of the new Federated Data Platform.
The admission followed a request from the National Data Guardian, the statutory office that advises the NHS on confidentiality. NHS England conceded the error and apologised, The Register reported.
“We recognise that the DPIA contained an error in how it described supplier access to data, so we are correcting that error, and we apologise for any confusion this has caused,” NHS England said in its response. DPIA stands for Data Protection Impact Assessment, the document meant to spell out exactly this.
What Palantir can actually see
The access sits inside the platform’s National Data Integration Tenant. NHS England confirmed back in May that some supplier staff can reach identifiable patient information there. The access is for specific technical purposes, under NHS direction.
The system is meant to help the NHS share data across the health service and clear the care backlog. Palantir won the £330m contract to build it in 2023, after landing £60m in COVID-era contracts without competition.
NHS England says the supplier access is technically necessary. The National Data Guardian, Nicola Byrne, is not so sure it can take that on trust. “As an independent body not involved in the platform’s operation, we are not in a position to independently verify that assessment,” she said in an updated statement.
The ‘no surprises’ problem
Byrne is the custodian of the Caldicott Principles, the rules that have governed NHS patient confidentiality since the 1990s. One of them is the “no surprises” principle. People should not be caught off guard by who can see their data.
That is the principle this breach cuts against. The error “has shown how quickly confidence erodes if the ‘no surprises’ principle is not upheld when it comes to who can access people’s data, and why,” Byrne said.
She added that the strength of public feeling reflects two things. People care deeply about the confidentiality of their records. Many also remain uneasy about Palantir’s role in the NHS. The topic, she noted, has always been political.
A typo, or a culture?
Critics see something worse than a slip. Sam Smith, coordinator at the campaign group medConfidential, said the framing lets NHS England off too lightly.
“NHS England claims it was little more than a typo, but this is the result of punishing their expert staff away from speaking truth to leadership,” Smith told The Register. He called it “another example of the culture of fear that NHS England has cultivated around the platform.”
The row lands as scrutiny of Palantir’s public-sector work intensifies across Europe. France has been dropping Palantir for a homegrown rival. France and Germany are backing a European alternative on sovereignty grounds. Britain, so far, is holding the opposite line.
NHS England says it will implement the National Data Guardian’s recommendations in full. Whether that restores trust is another matter. As with other fights over health data, the numbers may be small and the fix technical, yet the transparency question is the one that lingers.
Get the TNW newsletter
Get the most important tech news in your inbox each week.