NHS apologises and admits Palantir engineers have access to identifiable patient data – PublicTechnology
Skip to content
PublicTechnology
Credit: Crown Copyright/Open Government Licence v3.0
The central health service body has acknowledged the inaccuracy of claims previously made in a transparency document which indicated that only NHS staff were able to see such sensitive information
NHS England has issued an apology after admitting that employees from Palantir and other suppliers can access identifiable information related to individual patients via the Federated Data Platform.
In its previously published Data Protection Impact Assessment (DPIA) – a transparency document that is a statutory requirement for many public services engaged in the processing of citizens’ sensitive personal data – the NHS had claimed only health-service staff could access identifiable individual info via the FDP.
Recent reports, however, have claimed that representatives from the platform’s core supplier, Palantir, can also access this sensitive data. Following the emergence of these stories, independent adviser and scrutiniser Dr Nicola Byrne – who holds the post of National Data Guardian – wrote to the NHS requesting clarity on whether or not external contractors and supplier staff could see patient info.
In a newly published response, NHS England stressed that – outside of the inaccurate DPIA – “we have always been clear publicly and on our website that authorised users from the supplier will be granted access to data”.
But the statement from the health service went on to admit “within the DPIA we referred to only NHS England staff having access to directly identifiable patient data [but]… in fact some suppliers working for NHS England do have controlled access”.
“We recognise that the DPIA contained an error in how it described supplier access to data so we are correcting that error, and we apologise for any confusion this has caused,” the NHS said.
Related content
Palantir’s £250m government deal ‘represents a vote of confidence in the UK’, minister says
Government to spend up to £20m on ‘border flow’ contract with CIA-backed big data firm Palantir
Palantir platform ‘will be more secure than anything currently used in NHS’, minister says
Access is provided via the FDP’s National Data Integration Tenant system, as part of supporting which three Palantir engineers “currently have administrative-level access to the NDIT”, while “a further 33 engineers from a variety of suppliers have more limited project-specific access to work on specific data sets and tasks assigned by NHS England including writing code and assuring the development of new products”.
“In all cases they do not have permission to use the data for their own purposes – their role is strictly limited to supporting the safe running and maintenance of the platform,” the health service added. “The access is granted based on operational need and is time limited therefore the numbers can fluctuate over time. Within NDIT, engineers, operating under the instruction of NHS England, could access identifiable and de-identifiable patient data, however this would only be to provide specific technical support – patient data is not routinely accessed.”
In response to the NHS clarification, data guardian Dr Byrne said that she and her team will “continue to engage with the programme in our independent advisory role, providing advice on its documentation, transparency materials… [and] will continue to provide challenge where necessary, and advocate for practices that build and maintain public and professional trust”.
She added that “we continue to strongly support the programme’s ambition” – but acknowledged the prevalence and vehemence of concerns regarding the FDP, and the presence of its primary tech supplier.
“The intensity of interest and strength of public feeling on this issue appear to reflect not only how deeply many people care about the use of their data, and its confidentiality, but also continuing concern amongst some about Palantir’s role in the NHS,” Byrne said. “This topic has always been to some extent political. As such, people have a range of views. And public, professional and media scrutiny has only increased over time. This means that accuracy and transparency must remain central priorities for the NHS FDP programme. This incident has shown how quickly confidence erodes if the ‘no surprises’ principle [of NHS data use] is not upheld when it comes to who can access people’s data, and why.”
MPs on the Science, Innovation and Technology Committee recently issued a report stating that “Palantir shouldn’t play such a significant role in the UK public sector”, and naming the vendor “as the most concerning example of the public sector’s growing reliance on a small number of major technology providers, [also] including Microsoft and Amazon Web Services”.
The committee issued unequivocal guidance that government should exercise a break clause...