NHS apologises over Palantir patient data access

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- NHS England apologised and is correcting its Data Protection Impact Assessment (DPIA) for the Federated Data Platform after admitting it inaccurately claimed only health-service staff could see identifiable patient data.
- Palantir has three engineers with administrative-level access to the platform's National Data Integration Tenant, while a further 33 engineers from other suppliers hold more limited, project-specific access — all time-limited and granted on operational need.
- NHS England said it had always stated publicly on its website that authorised supplier users would be granted access, and stressed that supplier staff cannot use the data "for their own purposes," with patient data "not routinely accessed."
- National Data Guardian Dr Nicola Byrne, who requested clarity after reports surfaced, said the episode shows how "quickly confidence erodes if the 'no surprises' principle is not upheld" when it comes to who can access people's data and why.
- The Science, Innovation and Technology Committee recently stated "Palantir shouldn't play such a significant role in the UK public sector" and recommended the government exercise a break clause to let the NHS exit the FDP engagement in March 2027, either via an in-house replacement or an alternative UK provider.
Why it matters: The corrected DPIA gives the public the first concrete picture of supplier reach into identifiable NHS data — three Palantir engineers with admin-level access and 33 more from other suppliers on the platform. The committee's March 2027 exit recommendation, which groups Palantir with Microsoft and AWS, puts a single contract decision over a broader question of public-sector dependence on a handful of big tech vendors.



