NHS England rapped over inaccurate Palantir patient data disclosure
NHS England has admitted that a data protection document wrongly described who could access patient information, failing to disclose that staff from US contractor Palantir could view identifiable data within part of its Federated Data Platform. The admission followed a request for clarification from the National Data Guardian (NDG), an independent body that advises on health data confidentiality, and has renewed concerns about transparency and oversight of Palantir's expanding role within the NHS.
The error concerned the platform's National Data Integration Tenant, where Palantir staff can access identifiable patient data for specific technical purposes, a fact not accurately reflected in the Data Protection Impact Assessment. Palantir won a £330 million contract for the platform in 2023, having previously secured £60 million in uncompeted COVID-era NHS contracts. NHS England said it was correcting the error and apologised, while NDG Nicola Byrne warned that public trust erodes quickly when data access comes as a surprise, noting continued political sensitivity around Palantir's involvement. Campaign group medConfidential was more critical, calling the mistake a symptom of a "culture of fear" around the programme rather than a simple typo.
- NHS England wrongly omitted Palantir's access to identifiable patient data in official filing
- National Data Guardian prompted correction, warns trust erodes without transparency
- Critics say error reflects deeper governance issues in £330m NHS-Palantir contract