
NHS England has admitted that a data protection document inaccurately stated who could access patient information, failing to disclose that Palantir staff could view identifiable data held within part of its Federated Data Platform. The US spy-tech firm won a 330 million contract to provide the platform in 2023 after it was awarded 60 million in COVID-era contracts without competition. The system is designed to improve data sharing across the NHS in England and help tackle the backlog in patient care. In May, NHS England confirmed that Palantir staff can access identifiable patient information within the platform's National Data Integration Tenant, an arrangement that was not accurately reflected in its Data Protection Impact Assessment (DPIA). Following a request for clarification from the National Data Guardian (NDG), an independent statutory office that advises England's health and care system, NHS England admitted the error. "We recognize that the DPIA contained an error in how it described supplier access to data so we are correcting that error, and we apologize for any confusion this has caused," the quango said in a statement. "Clarity around supplier access is crucial to our program and we will continue to work closely with the National Data Guardian, the [data protection regulator] Information Commissioner's Office and our governance groups to ensure our information is clear." In an updated report, NDG Nicola Byrne said NHS England had confirmed that some external supplier staff supporting the platform can access identifiable patient information for specific technical purposes under its direction. "NHS England states that this access is technically necessary. As an independent body not involved in the platform's operation, we are not in a position to independently verify that assessment," she said. Byrne said the intensity of interest and strength of public feeling on this issue appear to reflect not only how deeply many people care about the use of their data, and its confidentiality, but also continuing concern among some about Palantir's role in the NHS. "This topic has always been to some extent political. As such, people have a range of views. And public, professional, and media scrutiny has only increased over time. This means that accuracy and transparency must remain central priorities for the NHS FDP programme," she said. The NDG is the custodian of the Caldicott Principles, a set of rules the NHS uses to govern patient confidentiality that originated in the 1990s. Byrne said NHS England's error in failing to disclose Palantir's access to patient information "has shown how quickly confidence erodes if the 'no surprises' Principle is not upheld when it comes to who can access people's data, and why." Sam Smith, medConfidential coordinator, told The Register: "NHS England claims it was little more than a typo, but this is the result of punishing their expert staff away from speaking truth to leadership. It is another example of the culture of fear that NHS England has cultivated around the platform. Palantir is not magic, but it does require competence to lead, manage, and use." NHS England commented: "The NHS has strict policies in place for managing access to patient data, and we are committed to being transparent about its use. We have published a detailed response to the issues raised by the National Data Guardian and are implementing the recommendations in full." (R)