NHS England Admits to Misstating Palantir’s Access to Patient Data
NHS England has admitted its data-protection paperwork failed to disclose that Palantir staff can see identifiable patient data. The privacy watchdog expressed concern over the lack of transparency, stating it cannot verify the access is necessary.
Background
In a request from the National Data Guardian, NHS England acknowledged an error in their Data Protection Impact Assessment (DPIA), which misstated who could access patients’ medical records. This admission followed reports by The Register.
What Palantir Can Access
Palantir staff have access to identifiable patient data within the National Data Integration Tenant of the Federated Data Platform, primarily for technical purposes under NHS direction. The system aims to facilitate data sharing across the health service.
Concerns and Implications
Nicola Byrne, the National Data Guardian, questioned the necessity of this access, stating they cannot independently verify it. She highlighted the "no surprises" principle, a Caldicott Principle that governs patient confidentiality in the NHS, which was violated by this error.
Sam Smith, coordinator at medConfidential, criticized NHS England’s response, suggesting that the issue runs deeper than a simple typo:
"NHS England claims it was little more than a typo, but this is the result of punishing their expert staff away from speaking truth to leadership."
The revelation has sparked concerns about transparency and public trust in the NHS’s handling of patient data.