Article URL: https://www.publictechnology.net/2026/08/03/health-and-social-care/nhs-apologises-and-admits-palantir-engineers-have-access-to-identifiable-patient-data/ Comments URL:…

NHS England has issued an apology after admitting that employees from Palantir and other suppliers can access identifiable information related to individual patients via the Federated Data Platform. In its previously published Data Protection Impact Assessment (DPIA) – a transparency document that is a statutory requirement for many public services engaged in the processing of citizens’ sensitive personal data – the NHS had claimed only health-service staff could access identifiable individual info via the FDP. Recent reports, however, have claimed that representatives from the platform’s core supplier, Palantir, can also access this sensitive data. Following the emergence of these stories, independent adviser and scrutiniser Dr Nicola Byrne – who holds the post of National Data Guardian – wrote to the NHS requesting clarity on whether or not external contractors and supplier staff could see patient info. In a newly published response, NHS England stressed that – outside of the inaccurate DPIA – “we have always been clear publicly and on our website that authorised users from the supplier will be granted access to data”. But the statement from the health service went on to admit “within the DPIA we referred to only NHS England staff having access to directly identifiable patient data [but]… in fact some suppliers working for NHS England do have controlled access”. “We recognise that the DPIA contained an error in how it described supplier access to data so we are correcting that error, and we apologise for any confusion this has caused,” the NHS said. Access is provided via the FDP’s National Data Integration Tenant system, as part of supporting which three Palantir engineers “currently have administrative-level access to the NDIT”, while “a further 33 engineers from a variety of suppliers have more limited project-specific access to work on specific data sets and tasks assigned by NHS England including writing code and assuring the development of new products”. “In all cases they do not have permission to use the data for their own purposes – their role is strictly limited to supporting the safe running and maintenance of the platform,” the health service added. “The access is granted based on operational need and is time limited therefore the numbers can fluctuate over time. Within NDIT, engineers, operating under the instruction of NHS England, could access identifiable and de-identifiable patient data, however this would only be to provide specific technical support – patient data is not routinely accessed.”