by

NHS gives patient data to Palantir

NHS England has handed external tech workers sweeping access to identifiable patient data inside its flagship Palantir-built platform.

The change affects the National Data Integration Tenant, known as the NDIT, which is described internally as a “safe haven for data”. It holds information before it is “pseudonymised” and moved into other systems.

The NDIT sits inside the Federated Data Platform, the much-hyped NHS system meant to stitch scattered health data into one place. Palantir won a £330 million (€387 million) contract in 2023 to build it.

Under the plan, NHS England has agreed to create an “admin” role for the system. An internal briefing seen by the FT says the role “permits unlimited access to non-NHSE staff” to the NDIT and its identifiable patient data.

Those external workers could include Palantir staff and consultants dragged in to work on the FDP.

The move breaks with current practice, where anyone working with the NDIT must apply for clear data access to specific datasets. The new arrangement gives selected outsiders a much broader pass.

The April briefing, written by a senior NHS data official, admits the change could create a “risk of loss of public confidence in safeguarding patient data and ensuring appropriate use and access to it”.

The broader access was originally meant only for NHS England employees with security clearance. External workers then asked for the same permissions, “as it is too inconvenient to apply for all of the necessary individual CDAs”.

The note added: “This is not only about Palantir, hence we have referred to non-NHSE staff, but there is currently considerable public interest and concern about how much access to patient data Palantir/Palantir staff have.”

The briefing recommends a cap on the number of external admins with NDIT access. It says access should be time-limited and regularly reviewed, which sounds like the sort of thing one might want before opening the patient-data biscuit tin.

Officials said the recommendation had been accepted in recent weeks. They insisted it would apply only to a small number of non-NHS staff.

Liberal Democrat technology committee member Martin Wrigley told the Financial Times that this somewhat cavalier attitude to data security demonstrated how this whole FDP project does not have security by design at its heart.

“The public will be rightfully concerned that data privacy is not the first concern,” Wrigley said.

NHS England has promised five data protections, including transparency about who can access data and what they can see. The briefing said “being sure exactly who is accessing what patient-identifiable data at any one time” was a top concern.

“The more people have unrestricted access, the less that aim can be met,” it added.

An NHS England spokesperson said: “The NHS has strict policies in place for managing access to patient data and carries out regular audits to ensure compliance — including monitoring the work of engineers helping to set up the central data collection platform that will track NHS performance and help improve care for patients.

“Anyone external requiring access must have government security clearance and be approved by a member of NHS England staff at director level or above.”

Palantir’s role in the FDP has become more controversial because of its US defence and immigration enforcement work. Its co-founder and chief executive Alex Karp has backed Donald Trump, which has not helped its bedside manner with NHS staff.

Some NHS workers have refused to work on the FDP because of ethical concerns about the company. Supporters say the platform can bring together operational data, including waiting lists and operating theatre schedules, to improve patient care.

A Palantir spokesperson said: “To the NHS, and all our customers, we are designated by law as a ‘data processor’, with our customers “data controllers” That means that Palantir software can only be used to process data precisely in line with the instruction of the customer. Using the data for anything else would not only be illegal but technically impossible due to granular access controls overseen by the NHS.”

 

TOPICS:
alex karp  ·  data security  ·  federated data platform  ·  health technology  ·  NDIT  ·  nhs england  ·  NHS privacy  ·  palantir  ·  patient data

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews