
The NHS has been forced into an apology after conceding that engineers working for Palantir, the US data-analytics firm at the centre of its flagship data programme, have had access to identifiable information about individual patients – contradicting what NHS England had previously told the public.
The admission relates to the Federated Data Platform (FDP), the £330m system built by Palantir and rolled out across the NHS in England with the aim of joining up data held in different parts of the health service and helping to clear the backlog in patient care.
At the heart of the row is a Data Protection Impact Assessment (DPIA) – a document that public bodies are legally required to publish when they process people’s sensitive personal data, setting out who can see it and why.
NHS England’s DPIA had stated that only its own staff could access identifiable patient information through the platform. That was not true.
Three Palantir engineers currently hold administrative-level access to the part of the system known as the National Data Integration Tenant (NDIT), where data is held before it is anonymised, while a further 33 engineers from various suppliers have more limited, project-specific access.
The discrepancy only came to light after Dr Nicola Byrne, the national data Guardian – the independent official who advises the health and care system on the confidential use of patient information – pressed NHS England for clarification.
Confronted with the error, NHS England admitted that its own paperwork had misled the public.
“We recognise that the DPIA contained an error in how it described supplier access to data so we are correcting that error, and we apologise for any confusion this has caused,” the health service said.
Byrne, whose office is the custodian of the Caldicott Principles that have governed patient confidentiality in the NHS since the 1990s, said the affair had shown “how quickly confidence erodes” when the principle that patients should not be taken by surprise about who can see their data is not upheld.
She added that the strength of public feeling on the issue reflected more than simply the immediate breach.
“The intensity of interest and strength of public feeling on this issue appear to reflect not only how deeply many people care about the use of their data, and its confidentiality, but also continuing concern amongst some about Palantir’s role in the NHS,” she said.
NHS England maintains that the level of access granted to supplier staff is technically necessary to run the platform.
Byrne has stopped short of endorsing that claim, saying her office is not in a position to independently verify it.
Palantir, which is also known for its work with intelligence and defence agencies including the CIA, won the FDP contract in 2023 after being awarded £60m in Covid-era contracts without a competitive tender process.
Ministers have previously defended the deal, with one describing it as a system that would be “more secure than anything currently used in NHS” and another calling the wider £250m government relationship with the company “a vote of confidence in the UK”.
NHS England has said it is committed to transparency over the use of patient data and will act on the National Data Guardian’s recommendations.
