The central health body in England has admitted that its earlier statement about who could view sensitive patient data was incorrect. Previously, the NHS claimed only staff within the health service had access to personal details of patients through a system known as the Federated Data Platform. This claim was later found to be inaccurate, as representatives from Palantir and other vendors were also able to access the information. The issue came to light after reports emerged about how supplier staff could see identifiable data. An independent expert, Dr Nicola Byrne, who serves as the National Data Guardian, asked for clarification on this matter. In response, NHS England acknowledged that supplier staff had been granted access to the data under certain conditions. The health service admitted that a mistake was made in its Data Protection Impact Assessment document. It apologized for the confusion and said it would correct the error in future communications.
Access to the system is provided through a part of the platform called the National Data Integration Tenant. Three engineers from Palantir currently have administrative-level access to this system. Additionally, around thirty-three engineers from various suppliers work on specific tasks and datasets with limited permissions. These individuals are not allowed to use the data for their own purposes, only to support the platform’s operation. Access is limited in time and based on what is needed for daily operations.
Dr Byrne, who oversees data protection efforts, said her team will continue to monitor the situation closely. She emphasized that while she supports the goals of the program, concerns about Palantir’s role remain significant. She noted that public and professional interest in this issue reflects deep concern about how personal data is handled. The debate around the use of Palantir’s technology has become politically charged. Different people hold varying opinions, and scrutiny from the public, professionals, and media has grown over time. As a result, the NHS must keep accuracy and openness at the heart of its approach.
A committee of MPs recently reviewed the situation and recommended that the NHS should have a way to exit its agreement with Palantir by March 2027. That committee also advised that the NHS should either build an in-house solution or find a UK-based alternative provider.
The concerns raised by experts and lawmakers show how important it is to maintain public trust in the handling of sensitive health data. The situation also brings attention to broader issues in how public services rely on a few major tech firms. This growing dependence raises questions about control, accountability, and long-term sustainability of such systems.
The NHS is now under pressure to ensure that all data access rules are clear, fair, and transparent. It must also balance the benefits of using advanced technology with the need to protect patient privacy.
The health service has started making changes to how it works with suppliers, aiming for more consistent standards. This includes applying the same accountability measures to all vendors, no matter where they are based. The goal is to reduce risks that come from placing too much control in the hands of any one company. By doing so, the system can better protect patient data even if ownership changes. The NHS is also moving forward with plans for a single patient record system that will be governed more strictly. These steps are meant to help build confidence in how health data is used across the country.
The debate over who controls patient information continues as the NHS tries to stay ahead of growing concerns. It remains a key challenge for public trust and data safety in the digital age.
IMAGE: Gage Skidmore from Surprise, AZ, United States of America / Wikimedia Commons (CC BY-SA 2.0)
This article passed automated originality and source-verification checks before publishing.
