Leaked NHS Briefing: Palantir staff granted "unlimited access" to identifiable patient data
A leaked NHS England internal briefing states that staff from Palantir and other external contractors are being granted "unlimited access" to identifiable patient data inside the Federated Data Platform (FDP). The document, reported by the Financial Times and written by a senior NHS England data official in April 2026, creates a new "admin" role giving non-NHS staff broad access to the National Data Integration Tenant (NDIT) - the part of the system holding patient records before they are pseudonymised.
Palantir is not a generic IT supplier. It is an AI and data integration company whose platforms are used across healthcare, defence, intelligence and government sectors. NHS England says Palantir is contractually barred from training AI on patient data or commercialising it.
Privacy is the headline story. The structural story is bigger. The NHS Federated Data Platform forms part of a wider trend towards public services becoming increasingly dependent on proprietary technology platforms maintained by external suppliers. The question is whether existing data protection and governance frameworks were designed to address an AI and data platform vendor operating inside that infrastructure, and what independent mechanisms exist to verify that contractual restrictions are being followed.
The Patients Association says patients were not consulted. The briefing itself acknowledges a "risk of loss of public confidence". MPs have described the move as "dangerous".
We'd like your views:
- The NHS Federated Data Platform forms part of a wider trend towards public services depending on proprietary technology platforms maintained by external suppliers. What independent mechanisms should exist to audit, verify, or, if needed, replace those platforms over time?
- NHS England says Palantir is barred from training AI on patient data. When a national healthcare system relies on an external AI and data platform provider, what independent mechanisms exist to verify that contractual restrictions are being followed?
- The Patients Association says patients were not consulted on a significant change to who has access to their data. What does meaningful patient consent look like once a national platform is already live?
- What safeguards should government require when awarding long-term AI and data infrastructure contracts that may become deeply embedded within public services?
Sources
- The Guardian — https://www.theguardian.com/society/2026/may/11/palantir-access-nhs-england-patient-data
- Reuters — https://www.reuters.com/world/uk/britains-nhs-grant-palantir-contractors-unlimited-access-patient-data-ft-reports-2026-05-11/
- Digital Health News — https://www.digitalhealth.net/2026/05/palantir-to-be-granted-unlimited-access-to-nhs-patient-data/
- The Register — https://www.theregister.com/databases/2026/05/12/nhs-england-confirms-palantir-staff-can-access-patient-data/
- Computing — https://www.computing.co.uk/news/2026/government/nhs-palantir-access-to-identifiable-patient-data
- Medact briefing (governance / FDP) — https://www.medact.org/2026/resources/briefings/briefing-palantir-fdp/
- NHS England (FDP overview) — https://www.england.nhs.uk/digitaltechnology/nhs-federated-data-platform/


