NHS apologises and admits Palantir engineers have access to identifiable patient data
Overview
NHS England has apologised after admitting that its Data Protection Impact Assessment incorrectly stated that only NHS staff could see identifiable patient data via the Federated Data Platform (FDP). The correction confirms that authorised engineers from Palantir and other suppliers do have controlled access to that data.
Details of Access
Access is provided through the FDP’s National Data Integration Tenant (NDIT) system. Three Palantir engineers currently have administrative‑level access to NDIT, while a further 33 engineers from various suppliers have more limited, project‑specific access to work on data sets and tasks assigned by NHS England, such as writing code and assuring development of new products. The NHS stresses that in all cases the engineers do not have permission to use the data for their own purposes; their role is strictly limited to supporting the safe running and maintenance of the platform. Access is granted based on operational need, is time‑limited, and the numbers can fluctuate over time. Within NDIT, engineers operating under NHS England’s instruction could access both identifiable and de‑identifiable patient data, but this would only be for specific technical support and patient data is not routinely accessed.
NHS Response and Correction
In its original DPIA, NHS England claimed that only health‑service staff could access identifiable individual information via the FDP. After reports indicated that Palantir representatives could also see this data, the NHS issued a response acknowledging the error: “within the DPIA we referred to only NHS England staff having access to directly identifiable patient data [but]… in fact some suppliers working for NHS England do have controlled access.” The health service apologised for any confusion caused and stated that, outside of the inaccurate DPIA, it has always been clear publicly and on its website that authorised supplier users will be granted access to data.
Independent Adviser Commentary
National Data Guardian Dr Nicola Byrne responded that she and her team will continue to engage with the programme in an independent advisory role, providing advice on documentation and transparency materials and challenging where necessary. She said they continue to strongly support the programme’s ambition but acknowledged the prevalence and vehemence of concerns about the FDP and Palantir’s role. Byrne noted that public feeling reflects deep concern about data confidentiality and continuing unease about Palantir’s involvement, adding that accuracy and transparency must remain central priorities for the NHS FDP programme.
Parliamentary Committee Recommendations
The Science, Innovation and Technology Committee issued a report stating that Palantir should not play such a significant role in the UK public sector and naming the vendor as the most concerning example of the public sector’s growing reliance on a small number of major technology providers, also including Microsoft and Amazon Web Services. The committee recommended that the government exercise a break clause enabling the NHS to exit the FDP engagement in March 2027 and then either develop an in‑house replacement or seek an alternative UK provider.
Public Reaction (Hacker News Comments)
Commenters expressed scepticism and concern about the implications of supplier access to patient data. Some representative remarks include:
"In all cases they do not have permission to use the data for their own purposes Oh, they don't have permission? probably fine then." – @jpfromlondon
"LRB had a great article about Palantir and the NHS in their latest issue. What I mostly enjoyed reading is the insight that their actual software is quite 'rubbish', something I have seen people mention in discussions here..." – @clydethefrog
"Is Palantir obsessed with medical records? If so why? This is worrying as there recently was a change in the Japanese PII law..." – @numpad0
"So, what is going to happen now? Someone in the UK government goes 'ooops, sorry' and Palantir gets to keep access to this data? Or are we just going to have another 10 year long enquiry..." – @gambiting
"This is insanely fucked up, but also unsurprising." – @jascination
These comments reflect a mix of distrust, calls for accountability, and broader worries about reliance on foreign technology firms for handling sensitive health data.
Sources
Related
- Dispatch
- Dispatch
- Dispatch
- Dispatch