NHS England has confessed that its own paperwork was wrong about who can see patients' medical records.
NHS England says a data-protection document underlying its Federated Data Platform wrongly described who can see patients' identifiable records. The document did not disclose the full extent of the arrangement, the health service admitted. In practice, staff at Palantir - the US data-analytics contractor that runs part of the platform - can view identifiable patient data. NHS England's admission followed a request for clarification from the National Data Guardian, the government's statutory adviser on how health data is used.
Data-protection paperwork exists so patients and regulators know who is looking at their records - when it's wrong, the safeguard doesn't fail loudly, it fails invisibly. Palantir's access sits inside a platform NHS England has spent years building to centralize health data across England, so an error here undercuts oversight of the very system meant to reassure people that centralization is safe. That the correction only surfaced after a statutory body asked the question, rather than through routine NHS disclosure, says something about how these checks currently work.
For a platform sold on the promise of tight data controls, getting the who-can-see-what paperwork wrong is not a great advert.